8.8

CVE-2024-45518

An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41, and 8.8.15 before Patch 46. It allows authenticated users to exploit Server-Side Request Forgery (SSRF) due to improper input sanitization and misconfigured domain whitelisting. This issue permits unauthorized HTTP requests to be sent to internal services, which can lead to Remote Code Execution (RCE) by chaining Command Injection within the internal service. When combined with existing XSS vulnerabilities, this SSRF issue can further facilitate Remote Code Execution (RCE).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZimbraCollaboration Version >= 10.0.0 < 10.0.9
ZimbraCollaboration Version8.8.15 Update-
ZimbraCollaboration Version8.8.15 Updatep1
ZimbraCollaboration Version8.8.15 Updatep10
ZimbraCollaboration Version8.8.15 Updatep11
ZimbraCollaboration Version8.8.15 Updatep12
ZimbraCollaboration Version8.8.15 Updatep13
ZimbraCollaboration Version8.8.15 Updatep14
ZimbraCollaboration Version8.8.15 Updatep15
ZimbraCollaboration Version8.8.15 Updatep16
ZimbraCollaboration Version8.8.15 Updatep17
ZimbraCollaboration Version8.8.15 Updatep18
ZimbraCollaboration Version8.8.15 Updatep19
ZimbraCollaboration Version8.8.15 Updatep2
ZimbraCollaboration Version8.8.15 Updatep20
ZimbraCollaboration Version8.8.15 Updatep21
ZimbraCollaboration Version8.8.15 Updatep22
ZimbraCollaboration Version8.8.15 Updatep23
ZimbraCollaboration Version8.8.15 Updatep24
ZimbraCollaboration Version8.8.15 Updatep25
ZimbraCollaboration Version8.8.15 Updatep26
ZimbraCollaboration Version8.8.15 Updatep27
ZimbraCollaboration Version8.8.15 Updatep28
ZimbraCollaboration Version8.8.15 Updatep29
ZimbraCollaboration Version8.8.15 Updatep3
ZimbraCollaboration Version8.8.15 Updatep30
ZimbraCollaboration Version8.8.15 Updatep31
ZimbraCollaboration Version8.8.15 Updatep32
ZimbraCollaboration Version8.8.15 Updatep33
ZimbraCollaboration Version8.8.15 Updatep34
ZimbraCollaboration Version8.8.15 Updatep35
ZimbraCollaboration Version8.8.15 Updatep37
ZimbraCollaboration Version8.8.15 Updatep4
ZimbraCollaboration Version8.8.15 Updatep40
ZimbraCollaboration Version8.8.15 Updatep41
ZimbraCollaboration Version8.8.15 Updatep42
ZimbraCollaboration Version8.8.15 Updatep43
ZimbraCollaboration Version8.8.15 Updatep44
ZimbraCollaboration Version8.8.15 Updatep45
ZimbraCollaboration Version8.8.15 Updatep5
ZimbraCollaboration Version8.8.15 Updatep6
ZimbraCollaboration Version8.8.15 Updatep7
ZimbraCollaboration Version8.8.15 Updatep8
ZimbraCollaboration Version8.8.15 Updatep9
ZimbraCollaboration Version9.0.0 Update-
ZimbraCollaboration Version9.0.0 Updatep0
ZimbraCollaboration Version9.0.0 Updatep1
ZimbraCollaboration Version9.0.0 Updatep10
ZimbraCollaboration Version9.0.0 Updatep11
ZimbraCollaboration Version9.0.0 Updatep12
ZimbraCollaboration Version9.0.0 Updatep13
ZimbraCollaboration Version9.0.0 Updatep14
ZimbraCollaboration Version9.0.0 Updatep15
ZimbraCollaboration Version9.0.0 Updatep16
ZimbraCollaboration Version9.0.0 Updatep19
ZimbraCollaboration Version9.0.0 Updatep2
ZimbraCollaboration Version9.0.0 Updatep20
ZimbraCollaboration Version9.0.0 Updatep21
ZimbraCollaboration Version9.0.0 Updatep23
ZimbraCollaboration Version9.0.0 Updatep24
ZimbraCollaboration Version9.0.0 Updatep24.1
ZimbraCollaboration Version9.0.0 Updatep25
ZimbraCollaboration Version9.0.0 Updatep26
ZimbraCollaboration Version9.0.0 Updatep27
ZimbraCollaboration Version9.0.0 Updatep3
ZimbraCollaboration Version9.0.0 Updatep33
ZimbraCollaboration Version9.0.0 Updatep34
ZimbraCollaboration Version9.0.0 Updatep35
ZimbraCollaboration Version9.0.0 Updatep36
ZimbraCollaboration Version9.0.0 Updatep37
ZimbraCollaboration Version9.0.0 Updatep38
ZimbraCollaboration Version9.0.0 Updatep39
ZimbraCollaboration Version9.0.0 Updatep4
ZimbraCollaboration Version9.0.0 Updatep40
ZimbraCollaboration Version9.0.0 Updatep5
ZimbraCollaboration Version9.0.0 Updatep6
ZimbraCollaboration Version9.0.0 Updatep7
ZimbraCollaboration Version9.0.0 Updatep7.1
ZimbraCollaboration Version9.0.0 Updatep8
ZimbraCollaboration Version9.0.0 Updatep9
ZimbraCollaboration Version10.1.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 20.52% 0.953
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-918 Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.